Privacy Policy
1. What we collect
| Data | Why |
|---|---|
| Username (stored as you typed it) and password (hashed, never stored in plain text and not reversible even by us) | Your Suprabots account login |
| Bot configuration (server, account nickname) | To run your bots |
| Microsoft/Xbox Live auth tokens for connected bot accounts | To keep bots signed in; we never see or store your Microsoft password |
| Scan history (players, mobs, blocks your bots have seen) | The scan map / scan history features |
| Stripe customer & subscription IDs, plan tier, billing status | To know what plan you're on. We never see or store your card number; Stripe handles that entirely |
We don't currently collect your email address, phone number, or physical address for a basic account.
What "hashed" means. When you set a password, we don't save the password itself. We run it through a one-way function (scrypt) and save only the scrambled result, along with a random value unique to your account called a "salt". The process only works in one direction: the same password always produces the same result, but there is no way to work backwards from the stored result to your original password. Not by us, and not by anyone who obtained a copy of our database. When you sign in, we scramble what you typed and compare it to the stored result; if they match, the password was correct.
This is different from encryption, which is designed to be reversible by whoever holds the key. Passwords should never be reversible, which is why we hash them instead. The practical consequence for you: we genuinely cannot tell you what your password is if you forget it, because we don't know it. The salt matters too: it means two people who happen to choose the same password still get completely different stored values, so cracking one account's password tells an attacker nothing about any other account.
2. Cookies
We use one cookie: a session token that keeps you logged in. It's required for the dashboard to work and isn't used for advertising or tracking across other sites.
3. Who we share data with
We share billing-relevant information (which plan you're on, your Stripe customer ID) with Stripe to process payments; see their own privacy policy for how they handle your card details. We don't sell your data, and we don't share it with anyone else except where required by law.
4. How long we keep it
We keep your account data for as long as your account exists. If you delete your account, we delete your bot configuration, scan history, and login credentials; billing history may be retained separately by Stripe as required for their own tax/accounting obligations.
5. Your choices
You can review and delete your bot accounts and scan history from the dashboard at any time. To delete your account entirely or request a copy of your data, contact us the same way you'd reach out for support.
6. Children's privacy
Suprabots isn't intended for anyone under 13, and we don't knowingly collect data from children under that age.
7. Changes to this policy
We may update this policy as the product changes. Material changes will be reflected here with an updated date at the top of this page.
8. Contact
Questions about this policy can be sent through the dashboard's support contact, once one exists. For now, reach out however you'd normally contact us.